Aggregator
IOC问题反馈及ALPHA平台问题反馈入口优化啦
3 months 2 weeks ago
专家分析师团队支撑IOC问题反馈!
【2025合作伙伴巡礼】拓界科技—具备侦察思维的综合电子数据取证厂商
3 months 2 weeks ago
拓界科技—具备侦察思维的综合电子数据取证厂商
New ICS Malware 'FrostyGoop' Targeting Critical Infrastructure
3 months 2 weeks ago
Cybersecurity researchers have discovered what they say is the ninth Industrial Control Systems (ICS)-focused malware that has been used in a disruptive cyber attack targeting an energy company in the Ukrainian city of Lviv earlier this January.
Industrial cybersecurity firm Dragos has dubbed the malware FrostyGoop, describing it as the first malware strain to directly use Modbus TCP
The Hacker News
2024攻防演练丨DayDayMap重保情报共享模块上线啦!
3 months 2 weeks ago
实时掌握,安全有我
How to Securely Onboard New Employees Without Sharing Temporary Passwords
3 months 2 weeks ago
The initial onboarding stage is a crucial step for both employees and employers. However, this process often involves the practice of sharing temporary first-day passwords, which can expose organizations to security risks.
Traditionally, IT departments have been cornered into either sharing passwords in plain text via email or SMS, or arranging in-person meetings to verbally communicate these
The Hacker News
Magento Sites Targeted with Sneaky Credit Card Skimmer via Swap Files
3 months 2 weeks ago
Threat actors have been observed using swap files in compromised websites to conceal a persistent credit card skimmer and harvest payment information.
The sneaky technique, observed by Sucuri on a Magento e-commerce site's checkout page, allowed the malware to survive multiple cleanup attempts, the company said.
The skimmer is designed to capture all the data into the credit card form on the
The Hacker News
Telegram 0day可导致攻击者将恶意安卓APK以视频形式发送
3 months 2 weeks ago
速修复
微软:是欧盟把Windows 内核的密钥交给了 CrowdStrike,触发蓝屏死机
3 months 2 weeks ago
15年前的一项协议成了背锅侠
“微软蓝屏死机”持续发酵,多家企业仍未恢复
3 months 2 weeks ago
Telegram零日漏洞被售卖数周:恶意APK文件可伪装成视频消息
3 months 2 weeks ago
利用该漏洞需要多步交互和授权
利用 Chrome 漏洞( CVE-2023-2033) 进行 Electron 中的 RCE 攻击
3 months 2 weeks ago
译者:知道创宇404实验室翻译组
原文链接:Weaponizing Chrome CVE-2023-2033 for RCE in Electron: Some Assembly Required
1 背景
我在一个应用程序的核心功能中,发现了一基于 React createElement 的 XSS 漏洞。该应用程序是一个包含桌面应用程序的漏洞赏金项目,我希望将此漏洞升级为在桌面应用...
重磅丨国家密码管理局发布第47号公告(附全文)
3 months 2 weeks ago
《数据流通安全标准化白皮书》正式发布
3 months 2 weeks ago
介绍数据流通安全发展现状,提出数据流通安全标准体系框架。
零信任落地的理想应用场景:攻防演练
3 months 2 weeks ago
如果攻击方已经进入内网,终端失陷,防守方还能怎么办?
Meta Given Deadline to Address E.U. Concerns Over 'Pay or Consent' Model
3 months 2 weeks ago
Meta has been given time till September 1, 2024, to respond to concerns raised by the European Commission over its "pay or consent" advertising model or risk-facing enforcement measures, including sanctions.
The European Commission said the Consumer Protection Cooperation (CPC) Network has notified the social media giant that the model adopted for Facebook and Instagram might potentially violate
The Hacker News
雷神众测漏洞周报2024.07.15-2024.07.21
3 months 2 weeks ago
以下内容,均摘自于互联网,由于传播,利用此文所提供的信息而造成的任何直接或间接的后果和损失,均由使用者本人负责,雷神众测以及文章作者不承担任何责任。
Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY Malware
3 months 2 weeks ago
The Computer Emergency Response Team of Ukraine (CERT-UA) has alerted of a spear-phishing campaign that targeted a scientific research institution in the country with malware known as HATVIBE and CHERRYSPY.
The agency attributed the attack to a threat actor it tracks under the name UAC-0063, which was previously observed targeting various government entities to gather sensitive information using
The Hacker News
The tap-estry of threats targeting Hamster Kombat players
3 months 2 weeks ago
ESET researchers have discovered threats abusing the success of the Hamster Kombat clicker game
Novel ICS Malware Sabotaged Water-Heating Services in Ukraine
3 months 2 weeks ago
Newly discovered "FrostyGoop" is the first ICS malware that can communicate directly with operational technology systems via the Modbus protocol.
Jai Vijayan, Contributing Writer